Re: Moving forward ...

Karl Barth <[email protected]> Thu, 26 Feb 2004 13:02:08 -0500
Newsgroups gmane.ietf.asrg.filtering
Message-ID <[email protected]>
From: "Craig Hughes" <[email protected]>
> On Feb 26, 2004, at 9:25 AM, <[email protected]> wrote:
>
> >> Similarly, adding spam scores or "convenience" functions
> >> (e.g. URLs) inside the body of an email should be prohibited.
> >> Anything that makes it so the downstream filter cannot see
> >> exactly the same message as
> >> the upstream filter is unstable (ie if you remove a filter in
> >> the chain, you've sabotaged training for all filters downstream).
> >
> > Agreed.
>
> There are likely certain cases where "tampering" with the message to
> modify it for the downstream is actually desirable though.  For
> example, removing viruses or other potentially damaging payload,
> defanging nasty MIME bits, etc.  I agree that generally you don't want
> to change things too much for the downstream folks, but on the other
> hand, sometimes you know there's a potential problem if you let things
> go through w/out rewriting them.
>
> C
>

There are two possible outcomes from this, since one presumably wants virus
scanning to occur before the MUA gets its mitts on it:

1. You can't train spam filters on viruses/worms/etc. The probable corollary
is that it's going to be a given that virus/worm content should be removed
from the mail stream when detected. It shouldn't even get to the spam
filter.

2. Spam and malware filtering must happen at the same time, before the user
has the opportunity to be stupid. Once again, viruses, etc., must be removed
from the mail system before delivery, regardless of spam tagging/processing.

Karl B.
Drexel University Postmaster